boxscore/security
Saturday, August 15, 2026 · all times UTC← 2026-08-14 · archive · 2026-08-16 →

926 CVEs published August 15, 2026: 149 critical, 404 high, 26 medium, 11 low; 0 in KEV; 12 with a public exploit reference; 336 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 901 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published58181462314152563
KEV catalog size1670

846 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux1262284736316779802730.17.8.0017+1247
microsoft442180313112194288378331.87.8.0038-182
google4946172140228187351.16.5.0023+48
red hat1423642216615818400.07.1.0025+126
apple2246576811229372.87.1.0027+2
canonical11149320000.09.9.0029+11
suse551220000.07.3.0022+5
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco315192590961427.57.8.0033+24
palo alto networks12270114101427.44.5.0019+2
fortinet7253612128624.06.0.0051-1
sonicwall1012354017216.77.8.0024+8
vmware01247012100.08.7.00440
netgear990054800.04.3.0031+9
ivanti38130033562.57.9.5751+3
checkpoint1541003240.09.3.2062+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache101238451207214020.87.5.0048+100
mozilla1734226501300.09.1.0031-1
gitlab132808162427.15.1.0026+13
github570520000.08.6.0041+5
docker140130100.05.7.0014+1
wordpress1412105250.08.8.3700+1
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.0031-1
ibm19230061139946710.37.5.0030+192
adobe6010022512217544.07.8.0036+46
progress1639112080912.68.1.0027+16
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
zohocorp472410000.08.8.0099+4
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1624150622614.29.3.0209+16
siemens192011612100.07.3.0011+19
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
elastic4867013540300.06.5.0027+48
siyuan-note5360298230000.08.8.0025+53
mongodb3258337162200.07.1.0024+32
surrealdb057326253000.07.1.0025-1
zephyrproject2749017266000.06.5.0016+26
gitea4848715224000.06.5.0027+48
netty34462891000.07.5.0046+3
grafana142314223000.06.5.0033-4

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-34486.829399.67.5
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
CVE-2026-0770.568899.09.8
CVE-2026-62144.206297.39.1
CVE-2026-9198.173596.99.8
CVE-2021-27137.164996.78.1
CVE-2026-15733.135496.19.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.1040KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4836210.0.0207
CVE-2026-1918810.0.0189
CVE-2026-7329910.0.0121
CVE-2026-4435910.0.0100
CVE-2026-4561810.0.0095
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
linux1913
oracle1108
microsoft463
google451
ibm292
red hat247
apache205
apple169
adobe75
elastic67
Most KEV additions (YTD)
VendorKEV
microsoft33
cisco14
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171732
CVE-2021-27102Accellion2021-11-171732
CVE-2021-27101Accellion2021-11-171732
CVE-2021-27103Accellion2021-11-171732
CVE-2021-21017Adobe2021-11-171732
CVE-2021-28550Adobe2021-11-171732
CVE-2021-42013Apache2021-11-171732
CVE-2021-41773Apache2021-11-171732
CVE-2021-30858Apple2021-11-171732
CVE-2021-30860Apple2021-11-171732

Transactions

EXPLOIT PUBLISHEDCVE-2020-0618 (Microsoft SQL Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-4034 (polkit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13712 (Unknown Divi). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15384 (Unknown Manual Image Crop). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17533 (Unknown All-in-One WP Migration and Backup). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18653 (Unknown WP Directory Kit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19613 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19711 (Unknown Premium Packages). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19712 (Unknown Masteriyo LMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19714 (Unknown Simple JWT Login). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19717 (Unknown CatFolders Document Gallery & PDF Library). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19725 (Unknown WPvivid — Backup, Migration & Staging). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19726 (Unknown Visualizer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19728 (Unknown Extra Product Options Builder for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19922 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19925 (SourceCodester Stock Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19927 (OpenBoxes). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19930 (Dolibarr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19933 (DefaultFuction Customer-Relationship-Management-In-C-Project). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19958 (iatsiuk pptr-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19961 (Edimax EW-7478APC). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19962 (Edimax EW-7478APC). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19963 (Edimax EW-7478APC). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19964 (Jij-Inc Jij-MCP-Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.

DUE DATE PASSEDCVE-2026-20349 (Cisco Secure Firewall Adaptive Security Appliance (ASA) Software). CISA remediation deadline was August 14, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-72898 (Metabase). CISA remediation deadline was August 14, 2026; still in catalog.

RESCOREDCVE-2020-0618 (Microsoft SQL Server). CVSS 9.8 → 8.8 (NVD).

RESCOREDCVE-2022-21882 (Microsoft Windows 10 Version 1809). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2022-49363 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2022-49519 (Linux). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2022-49770 (Linux). CVSS 9.8 → 7.8 (NVD).

RESCOREDCVE-2022-49974 (Linux). CVSS 8.8 → 5.5 (NVD).

RESCOREDCVE-2022-50393 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2022-50442 (Linux). CVSS 8.4 → 7.1 (NVD).

RESCOREDCVE-2023-32249 (Linux). CVSS 9.1 → 5.5 (NVD).

RESCOREDCVE-2023-3865 (Linux). CVSS 8.1 → 7.1 (NVD).

RESCOREDCVE-2023-3867 (Linux). CVSS 9.1 → 7.1 (NVD).

RESCOREDCVE-2023-4130 (Linux). CVSS 8.1 → 5.5 (NVD).

RESCOREDCVE-2023-52440 (Linux). CVSS 9.8 → 7.8 (NVD).

RESCOREDCVE-2023-52441 (Linux). CVSS 9.1 → 7.8 (NVD).

RESCOREDCVE-2023-52480 (Linux). CVSS 9.8 → 7 (NVD).

RESCOREDCVE-2026-32590 (Red Hat mirror registry for Red Hat OpenShift 2.0). CVSS 7.1 → 8.8 (NVD).

ENRICHEDCVE-2022-49360 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49361 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49364 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49380 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49518 (Linux). Received CVSS 7.1 and CPE data from NVD.

ENRICHEDCVE-2022-49520 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49528 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49543 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49833 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49966 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49969 (Linux). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2022-49983 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50009 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50013 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50015 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50016 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50026 (Linux). Received CVSS 7.1 and CPE data from NVD.

ENRICHEDCVE-2022-50034 (Linux). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2022-50151 (Linux). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2022-50206 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50223 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50256 (Linux). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2022-50262 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50273 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50316 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50336 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50451 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50479 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50527 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-50535 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2023-32246 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2023-52485 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2023-52506 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2023-52583 (Linux). Received CVSS 5.5 and CPE data from NVD.

Yesterday's Results

926 CVEs published. 25 box scores and 375 table rows below; the remaining 526 continue on page 2 — every CVE is listed, nothing truncated.

jackdewey Link Library — Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0121   65.7     —
AFFECTED
  Product       Versions     Fixed
  Link Library  unspecified  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 15  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 9 references · NVD status: Received
wpdevteam Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! — Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0098   59.4     —
AFFECTED
  Product                                                                                           Versions     Fixed
  Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 15  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 18 references · NVD status: Received
cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor — User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0080   53.8     —
AFFECTED
  Product                                                                                     Versions     Fixed
  User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Aug 15  Published (CNA: Wordfence)
CWE-704 · CNA: Wordfence · 9 references · NVD status: Received
pietror91 RapiSafe – Secure Multi File Upload for Contact Form 7 — RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0076   52.4     —
AFFECTED
  Product                                                 Versions     Fixed
  RapiSafe – Secure Multi File Upload for Contact Form 7  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 15  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 7 references · NVD status: Received
Linux Linux — ipvs: ensure inner headers in ICMP errors are in headroom
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e –  —
  Linux    3.7 –                                       5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — qede: fix off-by-one in BD ring consumption on build_skb failure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    8a8633978b842c88fbcfe00d4e5dde96048f630e –  —
  Linux    4.18 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — gue: validate REMCSUM private option length
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    c1aa8347e73e4092411fbd96cc59531fb7e76d04 –  —
  Linux    3.19 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0074   51.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    82cae269cfa953032fbb8980a7d554d60fb00b17 –  —
  Linux    5.15 –                                      5.15.212
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Received
Linux Linux — orangefs: keep the readdir entry size 64-bit in fill_from_part()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0074   51.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    480e3e532e31666a18520a7964bb4095d7a16b9a –  —
  Linux    4.12 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0074   51.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    82cae269cfa953032fbb8980a7d554d60fb00b17 –  —
  Linux    5.15 –                                      5.15.212
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Received
Linux Linux — scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4949314c7283ea4f9ade182ca599583b89f7edd6 –  —
  Linux    3.3 –                                       5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — ipv6: mcast: Fix potential UAF in MLD delayed work
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 –  —
  Linux    2.6.12 –                                    5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — net/9p: fix race condition on rdma->state in trans_rdma.c
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    473c7dd1d7b59ff8f88a5154737e3eac78a96e5b –  —
  Linux    4.20 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — scsi: target: Bound PR-OUT TransportID parsing to the received buffer
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5 –  —
  Linux    2.6.38 –                                    5.15.212
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Received
Linux Linux — nvmet-auth: reject short AUTH_RECEIVE buffers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    db1312dd95488b5e6ff362ff66fcf953a46b1821 –  —
  Linux    6.0 –                                       6.12.101
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 4 references · NVD status: Received
Linux Linux — xprtrdma: Fix bcall rep leak and unbounded peek
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    41c8f70f5a3db7e06179186b6525fd9ee1d7d314 –  —
  Linux    4.14 –                                      5.15.212
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Received
Linux Linux — afs: Fix callback service message parsers to pass through -EAGAIN
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0072   50.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 –  —
  Linux    4.9 –                                       5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — afs: Fix error code in afs_extract_vl_addrs()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0072   50.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    0a5143f2f89cc88d8a3eada8e8ccd86c1e988257 –  —
  Linux    4.20 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0072   50.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    460c112e1d887b58b06b56e8e0230058906ff2c3 –  —
  Linux    6.19 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    18f84d41d34fa35d0d64bbaea01fe664553ecc06 –  —
  Linux    4.2 –                                       6.1.178
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Received
Linux Linux — crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0070   50.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    10b4f09491bfeb0b298cb2f49df585510ee6189a –  —
  Linux    5.7 –                                       5.10.261
TIMELINE
  Aug 15  Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — ipvs: fix more places with wrong ipv6 transport offsets
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    2a3b791e6e1169f374224d164738e9f7be703d77 –  —
  Linux    2.6.28 –                                    5.10.261
TIMELINE
  Jul 30  Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9a05475cebdd6341884b5901e53870be26e65158 –  —
  Linux    3.10 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — nvmet-rdma: handle inline data with a nonzero offset
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349 –  —
  Linux    4.19 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Linux Linux — batman-adv: tt: prevent TVLV OOB check overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    7ea7b4a142758deaf46c1af0ca9ceca6dd55138b –  —
  Linux    3.13 –                                      5.10.261
TIMELINE
  Aug 9   Reserved by CNA
  Aug 15  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-722519.850.3LinuxLinuxnetfilter: nf_nat_sip: reload possible stale data pointer
CVE-2026-723989.850.3LinuxLinuxsctp: add INIT verification after cookie unpacking
CVE-2026-742679.850.3LinuxLinuxnet/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek befor…
CVE-2026-722969.150.3LinuxLinuxnet: ife: require ETH_HLEN to be pullable in ife_decode()
CVE-2026-722317.549.7LinuxLinuxbatman-adv: tt: avoid request storms during pending request
CVE-2026-722477.549.7LinuxLinuxnetfilter: nf_conncount: fix zone comparison in tuple dedup
CVE-2026-724097.549.7LinuxLinuxnet: mvneta: re-enable percpu interrupt on resume
CVE-2026-725027.549.7LinuxLinuxtcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
CVE-2026-742827.549.7LinuxLinuxtipc: prevent snt_unacked underflow on CONN_ACK
CVE-2026-722349.849.6LinuxLinuxbatman-adv: access unicast_ttvn skb->data only after skb realloc
CVE-2026-724647.549.2LinuxLinuxxprtrdma: Repost Receive buffers for malformed replies
CVE-2026-720149.849.2LinuxLinuxdrbd: reject data replies with an out-of-range payload size
CVE-2026-723999.849.1LinuxLinuxnet: enetc: check the number of BDs needed for xdp_frame
CVE-2026-724519.849.1LinuxLinuxxfrm: Fix xfrm state cache insertion race
CVE-2026-742817.549.0LinuxLinuxtipc: reject inverted service ranges from peer bindings
CVE-2026-724229.848.9LinuxLinuxksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
CVE-2026-724739.848.8LinuxLinuxxprtrdma: Decouple req recycling from RPC completion
CVE-2026-720659.848.7LinuxLinuxnet: mana: Validate the packet length reported by the NIC
CVE-2026-720699.848.7LinuxLinuxlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
CVE-2026-722999.848.7LinuxLinuxtipc: restrict socket queue dumps in enqueue tracepoints
CVE-2026-721497.548.4LinuxLinuxdmaengine: tegra: Fix burst size calculation
CVE-2026-724657.548.4LinuxLinuxxprtrdma: Sanitize the reply credit grant after parsing
CVE-2026-723179.848.3LinuxLinuxSUNRPC: pin upper rpc_clnt across the TLS connect_worker
CVE-2026-723819.848.3LinuxLinuxksmbd: fix use-after-free of fp->owner.name in durable handle owner check
CVE-2026-720989.848.0LinuxLinuxdm-verity: fix buffer overflow in FEC calculation
CVE-2026-723239.847.9LinuxLinuxipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
CVE-2026-724729.847.9LinuxLinuxnfs: use nfsi->rwsem to protect traversal of the file lock list
CVE-2026-723108.147.8LinuxLinuxsmb: client: fix overflow in passthrough ioctl bounds check
CVE-2026-723669.847.8LinuxLinuxnetfs: Fix netfs_create_write_req() to handle async cache object creation
CVE-2026-721078.847.4LinuxLinuxdm era: fix out-of-bounds memory access for non-zero start sector
CVE-2026-721608.847.4LinuxLinuxocfs2: reject dinodes with non-canonical i_mode type
CVE-2026-723307.547.3LinuxLinuxnet/tls: Consume empty data records in tls_sw_read_sock()
CVE-2026-723567.547.3LinuxLinuxcifs: Fix missing credit release on failure in cifs_issue_read()
CVE-2026-684769.847.1LinuxLinuxipvs: reload ip header after head reallocation
CVE-2026-720419.847.1LinuxLinuxespintcp: use sk_msg_free_partial to fix partial send
CVE-2026-720469.847.1LinuxLinuxgve: fix header buffer corruption with header-split and HW-GRO
CVE-2026-721379.847.1LinuxLinuxxfrm: nat_keepalive: avoid double free on send error
CVE-2026-721859.847.1LinuxLinuxntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
CVE-2026-722179.847.1LinuxLinuxSUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
CVE-2026-722219.847.1LinuxLinuxsunrpc: wait for in-flight TLS handshake callback when cancel loses race
CVE-2026-722229.847.1LinuxLinuxsunrpc: pin svc_xprt across the asynchronous TLS handshake callback
CVE-2026-723489.147.1LinuxLinuxnetfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
CVE-2026-723737.546.9LinuxLinuxafs: Fix missing NULL pointer check in afs_break_some_callbacks()
CVE-2026-721919.846.7LinuxLinuxntfs3: validate split-point offset in indx_insert_into_buffer
CVE-2026-156899.846.2ABEVERLEYDancer2::Plugin::Auth::ExtensibleCWE-640Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow passw…
CVE-2026-724299.846.1LinuxLinuxipv6: ioam: fix type confusion of dst_entry
CVE-2026-742689.846.1LinuxLinuxtcp: clear sock_ops cb flags before force-closing a child socket
CVE-2026-722427.545.6LinuxLinuxselinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
CVE-2026-722537.545.6LinuxLinuxnetfilter: nf_conntrack_sip: validate skb_dst() before accessing it
CVE-2026-722547.545.6LinuxLinuxnetfilter: nft_fib: reject fib expression on the netdev egress hook
CVE-2026-723828.845.4LinuxLinuxksmbd: reject undersized DACLs before parsing ACEs
CVE-2026-721399.845.4LinuxLinuxtcp: defer md5sig_info kfree past RCU grace period in tcp_connect
CVE-2026-722209.845.4LinuxLinuxsunrpc: harden rq_procinfo lifecycle to prevent double-free
CVE-2026-723939.845.4LinuxLinuxeth: fbnic: don't cache shinfo across skb realloc
CVE-2026-723189.445.3LinuxLinuxcifs: validate DFS referral string offsets
CVE-2026-721417.545.1LinuxLinuxi2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
CVE-2026-723678.845.0LinuxLinuxiomap: guard io_size EOF trim against concurrent truncate underflow
CVE-2026-159658.844.9sadathimelMaxUpload – Big File Uploads – Increase Maximum File Upload SizeCWE-434MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFile…
CVE-2026-720218.245.0LinuxLinuxipvs: use parsed transport offset in SCTP state lookup
CVE-2026-721008.844.0LinuxLinuxdm-integrity: fix a bug if the bio is out of limits
CVE-2026-7242110.043.7LinuxLinuxipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-723559.843.6LinuxLinuxnetfs: Fix barriering when walking subrequest list
CVE-2026-720649.843.6LinuxLinuxnet: mana: Sync page pool RX frags for CPU
CVE-2026-724179.843.6LinuxLinuxnetfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
CVE-2026-724429.843.6LinuxLinuxnetfilter: flowtable: fix and simplify IP6IP6 tunnel handling
CVE-2026-720578.243.6LinuxLinuxnet/sched: act_ct: preserve tc_skb_cb across defragmentation
CVE-2026-743949.843.3LinuxLinuxRDMA/srpt: fix integer overflow in immediate data length check
CVE-2026-736347.543.0Apache Software FoundationApache StrutsCWE-400Apache Struts: Unbounded read of a Content Security Policy violation report
CVE-2026-720358.242.7LinuxLinuxnet/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeu…
CVE-2026-723209.142.0LinuxLinuxnetfilter: nft_lookup: fix catchall element handling with inverted lookups
CVE-2026-7427910.041.8LinuxLinuxcrypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-743849.841.8LinuxLinuxnvme-multipath: fix flex array size in struct nvme_ns_head
CVE-2026-743989.841.8LinuxLinuxipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
CVE-2026-742879.141.8LinuxLinuxsctp: validate embedded address parameter length
CVE-2026-743967.541.7LinuxLinuxRDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
CVE-2026-7240710.041.5LinuxLinuxgeneve: validate inner network offset in geneve_gro_complete()
CVE-2026-721999.841.6LinuxLinuxntfs: validate resident index root values on lookup
CVE-2026-722009.841.6LinuxLinuxntfs: detect mapping-pairs LCN accumulator overflow
CVE-2026-722019.841.6LinuxLinuxntfs: validate index entries on reading
CVE-2026-722069.841.6LinuxLinuxntfs: validate index block header more strictly
CVE-2026-722079.841.6LinuxLinuxntfs: not change 0-byte $DATA attribute to non-resident
CVE-2026-722089.841.6LinuxLinuxntfs: add bounds check before accessing EA entries
CVE-2026-722099.841.5LinuxLinuxntfs: validate attribute values on lookup
CVE-2026-722109.841.6LinuxLinuxntfs: fix off-by-one in mapping pairs decoding bounds checks
CVE-2026-722119.841.6LinuxLinuxntfs: grow index root value before reparent header update
CVE-2026-722489.841.5LinuxLinuxnetfilter: flowtable: support IPIP tunnel with direct xmit
CVE-2026-722499.841.5LinuxLinuxnetfilter: flowtable: use dst in this direction when pushing IPIP header
CVE-2026-724779.841.5LinuxLinuxfs/ntfs3: call _ntfs_bad_inode() when failing to rename
CVE-2026-731949.141.3DBICWE-1284DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an un…
CVE-2026-743769.841.1LinuxLinuxmd/raid10: reset read_slot when reusing r10bio for discard
CVE-2026-744789.841.1LinuxLinuxum: vector: fix use-after-free in vector_mmsg_rx()
CVE-2026-723538.841.0LinuxLinuxntfs: avoid stale runlist element dereference in fallocate
CVE-2026-723548.841.0LinuxLinuxntfs: avoid stale runlist element dereference in MFT writeback
CVE-2026-743217.541.0LinuxLinuxbtrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
CVE-2026-742559.840.9LinuxLinuxtipc: fix UAF in tipc_l2_send_msg()
CVE-2026-744069.840.4LinuxLinuxvxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
CVE-2026-731939.840.3DBICWE-190DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit…
CVE-2026-684579.139.6LinuxLinuxksmbd: use opener credentials for FSCTL mutations
CVE-2026-198982.939.5n/aVictoriaMetricsCWE-307VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessi…
CVE-2026-724928.839.2LinuxLinuxksmbd: fix use-after-free in same_client_has_lease()
CVE-2026-722027.538.5LinuxLinuxntfs: avoid heap allocation for free-cluster readahead state
CVE-2026-722037.538.5LinuxLinuxntfs: skip extent mft records in writeback to prevent deadlock
CVE-2026-721869.138.5LinuxLinuxntfs: make system files immutable to prevent corruption
CVE-2026-721889.138.5LinuxLinuxntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()
CVE-2026-736357.538.0Apache Software FoundationApache StrutsCWE-770Apache Struts: Unbounded growth of localized-text caches driven by the reques…
CVE-2026-720997.138.0LinuxLinuxdm-integrity: don't increment hash_offset twice
CVE-2026-744739.837.9LinuxLinuxvxlan: use pskb_network_may_pull() in route_shortcircuit()
CVE-2026-744809.837.9LinuxLinuxnet: bridge: stop fast-leave after deleting a port group
CVE-2026-744959.837.9LinuxLinuxigbvf: Fix leak in TX DMA error cleanup
CVE-2026-745459.837.9LinuxLinuxrtase: fix double free of multi-frag skb on DMA map failure
CVE-2026-744769.137.9LinuxLinuxveth: convert frag_list skbs before running XDP
CVE-2026-199008.237.7LB-LINKX-PROCWE-798LB-LINK X-PRO shadow hard-coded credentials
CVE-2026-199018.237.7LB-LINKX-PROCWE-259LB-LINK X-PRO easycwmp hard-coded credentials
CVE-2026-743459.837.4LinuxLinuxRDMA/siw: Fix endpoint/socket association handling
CVE-2026-744019.837.4LinuxLinuxdlm: fix add msg handle in send_queue ordered
CVE-2026-7430910.037.2LinuxLinuxvdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-743619.837.2LinuxLinuxnvme: fix FDP fdpcidx bounds check
CVE-2026-743167.537.1LinuxLinuxNFSD: Handle layout stid in nfsd4_drop_revoked_stid()
CVE-2026-724208.837.0LinuxLinuxmd/raid5: avoid R5_Overlap races while breaking stripe batches
CVE-2026-744939.837.0LinuxLinuxnet/smc: fix socket use-after-free during link group termination
CVE-2026-153039.836.8sixstorage6Storage RentalsCWE-2876Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Par…
CVE-2026-744749.836.8LinuxLinuxvxlan: use pskb_network_may_pull() for transmit path header pulls
CVE-2026-745237.536.7LinuxLinuxqede: sync udp_tunnel ports outside qede_lock in the recovery path
CVE-2026-745507.536.7LinuxLinuxnet: do not send ICMP/NDISC Redirects when peer allocation fails
CVE-2026-743857.536.0LinuxLinuxnvmet-tcp: check return value of nvmet_tcp_set_queue_sock
CVE-2026-195989.835.6sc0ttkclarkPods – Custom Content Types and FieldsCWE-863Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass…
CVE-2026-730469.335.5siyuan-notesiyuanCWE-307SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth
CVE-2026-744698.834.6LinuxLinuxsctp: prevent peer transport count overflow
CVE-2026-122486.534.2WPMLWPML Multilingual CMSCWE-89WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection vi…
CVE-2026-7240810.033.9LinuxLinuxgeneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-724639.833.9LinuxLinuxxfrm: Fix dev use-after-free in xfrm async resumption
CVE-2026-724949.833.9LinuxLinuxRDMA/irdma: Replace waitqueue and flag with completion
CVE-2026-7476410.033.7pandora-analysispandoraCWE-22Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora
CVE-2026-744279.833.6LinuxLinuxafs: Fix netns teardown to cancel the preallocation charger
CVE-2026-720298.833.5LinuxLinuxnet: wwan: iosm: bound device offsets in the MUX downlink decoder
CVE-2026-744908.833.6LinuxLinuxtipc: avoid use-after-free in poll trace queue dumps
CVE-2026-745228.833.6LinuxLinuxksmbd: fix use-after-free in __close_file_table_ids()
CVE-2026-198952.933.4opensourceposOpen Source Point of SaleCWE-307opensourcepos Open Source Point of Sale Login Endpoint Filters.php index exce…
CVE-2026-7447510.033.0LinuxLinuxvxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-183876.532.3trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-89Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' …
CVE-2026-150018.832.1connectordevbLoyal: Loyalty & Promotions by bLoyalCWE-269bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscri…
CVE-2026-742699.831.1LinuxLinuxbnxt: fix head underflow on XDP head-grow
CVE-2026-743159.831.1LinuxLinuxlockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file()
CVE-2026-743509.831.1LinuxLinuxocfs2: validate fast symlink target during inode read
CVE-2026-161429.830.8themetechmountTrueBooker – Appointment Booking and Scheduler SystemCWE-639TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Ob…
CVE-2026-745767.530.7LinuxLinuxmm/slab: prevent unbounded recursion in free path with new kmalloc type
CVE-2026-724939.930.5LinuxLinuxnet: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-730439.430.3siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Remote Code Execution via Template Calculation
CVE-2026-198972.930.1mangroupdtaleCWE-307mangroup dtale Login Endpoint auth.py login excessive authentication
CVE-2026-744369.829.5LinuxLinuxrxrpc: serialize kernel accept preallocation with socket teardown
CVE-2026-724407.129.5LinuxLinuxmd/raid1: fix writes_pending and barrier reference leaks on write failures
CVE-2026-745569.829.0LinuxLinuxscsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
CVE-2026-724387.529.0LinuxLinuxmd/raid10: fix writes_pending and barrier reference leaks on discard failures
CVE-2026-744289.828.2LinuxLinuxrxrpc: Fix double unlock in rxrpc_recvmsg()
CVE-2026-744339.828.2LinuxLinuxrxrpc: Fix UAF in rxgk_issue_challenge()
CVE-2026-744257.528.1LinuxLinuxafs: handle CB.InitCallBackState3 requests without a server record
CVE-2026-744357.528.1LinuxLinuxrxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
CVE-2026-745699.827.9LinuxLinuxnetfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
CVE-2026-121285.327.9dotonpaperPinpoint Booking System – Version 2CWE-20Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validat…
CVE-2026-745727.527.6LinuxLinuxbtrfs: zoned: fix deadlock between metadata writeback and transaction commit
CVE-2026-160944.927.6matthiasnordwigInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All FormsCWE-89Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection …
CVE-2026-720038.827.4LinuxLinuxwifi: brcmfmac: cyw: fix heap overflow on a short auth frame
CVE-2026-151627.527.3minnpostObject Sync for SalesforceCWE-89Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection
CVE-2026-743747.527.3LinuxLinuxmd/raid1,raid10: fix error-path detection with md_cloned_bio()
CVE-2026-744349.827.2LinuxLinuxrxrpc: Don't move a peeked OOB message onto the pending queue
CVE-2026-743418.827.3LinuxLinuxwifi: wcn36xx: fix heap overflow from oversized firmware HAL response
CVE-2026-723348.827.1LinuxLinuxBluetooth: ISO: fix malformed ISO_END/CONT handling
CVE-2026-185497.527.0@fastify/multipart@fastify/multipartCWE-400@fastify/multipart vulnerable to Denial of Service via aborted upload after f…
CVE-2026-722338.826.9LinuxLinuxbatman-adv: bla: reacquire gw address after skb realloc
CVE-2026-722358.826.9LinuxLinuxbatman-adv: retrieve ethhdr after potential skb realloc on RX
CVE-2026-744297.526.8LinuxLinuxrxrpc: Fix the reception of a reply packet before data transmission
CVE-2026-744307.526.8LinuxLinuxrxrpc: Fix ACKALL packet handling
CVE-2026-744317.526.8LinuxLinuxrxrpc: Fix potential infinite loop in rxrpc_recvmsg()
CVE-2026-722278.126.5LinuxLinuxbatman-adv: mcast: avoid OOB read of num_dests header
CVE-2026-153419.826.2rafasashiUser Session SynchronizerCWE-287User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to…
CVE-2026-721218.826.2LinuxLinuxcan: bcm: add locking when updating filter and timer values
CVE-2026-721248.826.2LinuxLinuxcan: isotp: serialize TX state transitions under so->rx_lock
CVE-2026-721578.826.2LinuxLinuxnet: thunderbolt: Fix frags[] overflow by bounding frame_count
CVE-2026-199066.325.7pkppkp-libCWE-331pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
CVE-2026-165866.525.7contest-galleryContest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeCWE-89Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injectio…
CVE-2026-721488.825.0LinuxLinuxdmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
CVE-2026-684718.824.5LinuxLinuxwifi: ieee80211: validate MLE common info length
CVE-2026-724698.824.5LinuxLinuxxprtrdma: Fix ep kref imbalance on ADDR_CHANGE
CVE-2026-745219.124.2LinuxLinuxksmbd: use memcmp() to compare ClientGUIDs
CVE-2026-88405.324.2wpdevartBooking calendar, Appointment Booking SystemCWE-862Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorizatio…
CVE-2026-724717.124.2LinuxLinuxfs/ntfs3: prevent potential lcn remains uninitialized
CVE-2026-730548.724.1siyuan-notesiyuanCWE-287SiYuan before v3.7.4 Authentication Bypass via WebSocket
CVE-2026-199035.523.8SourceCodesterOnline Clothing StoreCWE-552SourceCodester Online Clothing Store SQL Database Backup shopping.sql file ac…
CVE-2026-159935.323.810webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-89Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection vi…
CVE-2026-745709.823.4LinuxLinuxntfs: harden runlist realloc size calculations
CVE-2026-198962.923.4mangroupdtaleCWE-310mangroup dtale Flask Session Cookie app.py build_secret_key random values
CVE-2026-730458.722.8siyuan-notesiyuanCWE-307SiYuan before 3.7.4 Brute-Force via authFilePublishAccess
CVE-2026-730429.422.5siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Remote Code Execution via Menu Metadata
CVE-2026-730529.422.5siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names
CVE-2026-684728.122.4LinuxLinuxwifi: cfg80211: validate EHT MLE before MLD ID read
CVE-2026-161464.922.0matthiasnordwigInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All FormsCWE-89Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection …
CVE-2026-745577.521.7LinuxLinuxscsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
CVE-2026-723808.821.4LinuxLinuxxen/pvcalls: bound backend response req_id before indexing rsp[]
CVE-2026-684708.821.4LinuxLinuxwifi: mac80211: validate extension-frame layout before RX
CVE-2026-182166.521.1UnknownBackup MigrationCWE-287Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-…
CVE-2026-198932.321.1D-LinkDIR-842CWE-266D-Link DIR-842 vsftpd vsftpd.conf default permission
CVE-2026-730539.420.9siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji
CVE-2026-142798.820.8cedcommerceWholesale MarketCWE-269Wholesale Market <= 2.2.2 - Authenticated (Subscriber+) Privilege Escalation …
CVE-2026-153128.820.8fassionstoragePropovoice: All-in-One Client Management SystemCWE-269Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndp…
CVE-2026-721158.120.6LinuxLinuxcan: bcm: track a single source interface for ANYDEV timeout/throttle ops
CVE-2026-744108.120.3LinuxLinuxwifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer
CVE-2026-194747.520.3@fastify/multipart@fastify/multipartCWE-459@fastify/multipart vulnerable to Denial of Service via temporary file leak on…
CVE-2026-743408.120.2LinuxLinuxwifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
CVE-2026-744088.818.5LinuxLinuxwifi: ath9k: fix OOB access from firmware tx status queue ID
CVE-2026-161457.218.6matthiasnordwigInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All FormsCWE-79Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scri…
CVE-2026-198995.518.2SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection
CVE-2026-199195.518.2code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System Login login.php sql injection
CVE-2026-743008.817.8LinuxLinuxBluetooth: hci: validate codec capability element length
CVE-2026-744118.817.5LinuxLinuxwifi: rtw89: Correct data type for scan index to avoid infinite loop
CVE-2026-166117.517.4UnknownProduct Feed PRO for WooCommerce by AdTribesCWE-200Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuratio…
CVE-2026-745088.817.1LinuxLinuxBluetooth: HIDP: reject frames without a transaction header
CVE-2026-745318.817.1LinuxLinuxBluetooth: hci_conn: hold conn reference in abort_conn_sync()
CVE-2026-199055.517.1JinherOACWE-74Jinher OA attendance_out_approve.aspx sql injection
CVE-2026-747678.716.9pandora-analysispandoraCWE-434Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompres…
CVE-2026-198942.116.6itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewmedicine.php sql injection
CVE-2026-745398.016.5LinuxLinuxBluetooth: ISO: lock sk in iso_sock_getname
CVE-2026-154536.516.5iqonicdesignKiviCare – Clinic & Patient Management System (EHR)CWE-89KiviCare <= 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Pa…
CVE-2026-160806.516.5fishpieImage Uploader for WelcartCWE-89Image Uploader for Welcart <= 1.4.6 - Authenticated (Author+) SQL Injection v…
CVE-2026-730449.416.3siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width
CVE-2026-730509.416.3siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Stored XSS via select option color
CVE-2026-744888.816.2LinuxLinuxwifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
CVE-2026-745408.816.2LinuxLinuxBluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
CVE-2026-745418.816.2LinuxLinuxBluetooth: ISO: clear iso_data always when detaching conn from hcon
CVE-2026-133607.216.2wplegalpagesWPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeCWE-79Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored C…
CVE-2026-744098.815.7LinuxLinuxwifi: rtw89: add bounds check on firmware mac_id in link lookup
CVE-2026-744128.815.7LinuxLinuxwifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
CVE-2026-744138.815.7LinuxLinuxwifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
CVE-2026-743238.815.6LinuxLinuxwifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
CVE-2026-745358.815.5LinuxLinuxBluetooth: ISO: avoid deadlocks in iso_sock_timeout
CVE-2026-745348.815.2LinuxLinuxBluetooth: ISO: fix refcounting of iso_conn
CVE-2026-745378.815.2LinuxLinuxBluetooth: ISO: hold sk properly in iso_conn_ready
CVE-2026-745388.815.2LinuxLinuxBluetooth: ISO: lock sk in iso_connect_ind
CVE-2026-144337.214.9vcitaOnline Booking & Scheduling Calendar for WordPress by vcitaCWE-79Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauth…
CVE-2026-745098.814.6LinuxLinuxBluetooth: hci_sync: Fix advertising data UAFs
CVE-2026-743567.414.7LinuxLinuxvhost: fix vhost_get_avail_idx for a non empty ring
CVE-2026-170906.414.6beaverbuilderBeaver Builder Page Builder – Drag and Drop Website BuilderCWE-79Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cros…
CVE-2026-730419.414.5siyuan-notesiyuanCWE-79SiYuan before v3.7.4 Remote Code Execution via PDF Annotations
CVE-2026-745077.114.2LinuxLinuxBluetooth: HIDP: validate numbered report payloads
CVE-2026-745758.814.0LinuxLinuxthunderbolt: Prevent XDomain delayed work use-after-free on disconnect
CVE-2026-745288.014.0LinuxLinuxBluetooth: hci_sync: hold conn in hci_past_sync() callback
CVE-2026-736314.313.7Apache Software FoundationApache StrutsCWE-567Apache Struts: Shared parsing state in the JSON plugin
CVE-2026-736324.313.7Apache Software FoundationApache StrutsCWE-567Apache Struts: Shared serialization state in the JSON plugin
CVE-2026-199182.113.8SpaceXStarlink Router Gen 3CWE-266SpaceX Starlink Router Gen 3 gRPC Management get_status access control
CVE-2026-72441await13.6LinuxLinuxieee802154: fix kernel-infoleak in dgram_recvmsg()
CVE-2026-72245await12.9LinuxLinuxgpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
CVE-2026-72056await12.7LinuxLinuxnet: ena: clean up XDP TX queues when regular TX setup fails
CVE-2026-72068await12.7LinuxLinuxposix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
CVE-2026-72074await12.7LinuxLinuxInput: ims-pcu - fix type confusion in CDC union descriptor parsing
CVE-2026-72076await12.7LinuxLinuxInput: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
CVE-2026-72078await12.7LinuxLinuxInput: ims-pcu - validate control endpoint type
CVE-2026-72079await12.7LinuxLinuxInput: ims-pcu - fix use-after-free and double-free in disconnect
CVE-2026-72223await12.7LinuxLinuxnvdimm/btt: Free arena sub-allocations on discover_arenas() error path
CVE-2026-72224await12.7LinuxLinuxnvdimm/btt: Free arenas on btt_init() error paths
CVE-2026-72307await12.7LinuxLinuxmlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
CVE-2026-72316await12.7LinuxLinuxdm era: fix NULL pointer dereference in metadata_open()
CVE-2026-72326await12.7LinuxLinuxnet/sched: cake: reject overhead values that underflow length
CVE-2026-72349await12.7LinuxLinuxnetfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
CVE-2026-72396await12.7LinuxLinuxhwmon: adm1275: Prevent reading uninitialized stack
CVE-2026-72414await12.7LinuxLinuxnet: dsa: sja1105: round up PTP perout pin duration
CVE-2026-72447await12.7LinuxLinuxsctp: hold socket lock when dumping endpoints in sctp_diag
CVE-2026-165416.512.6UnknownSimply Schedule AppointmentsCWE-200Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure…
CVE-2026-72073await12.7LinuxLinuxmmc: vub300: fix use-after-free on probe failure
CVE-2026-744078.812.5LinuxLinuxwifi: ath11k: cancel SSR work items during PCI shutdown
CVE-2026-744898.812.6LinuxLinuxwifi: mac80211: fix tid_tx use-after-free on BA session stop
CVE-2026-745308.812.6LinuxLinuxBluetooth: hci_sync: hold conn in hci_connect_big_sync() callback
CVE-2026-745338.812.6LinuxLinuxBluetooth: ISO: fix race of kfree vs kref_get_unless_zero
CVE-2026-72106await12.3LinuxLinuxdm-ioctl: fix a possible overflow in list_version_get_info
CVE-2026-72058await12.1LinuxLinuxnet: ixp4xx_hss: fix duplicate HDLC netdev allocation
CVE-2026-72059await12.1LinuxLinuxnet: wwan: t7xx: destroy DMA pool on CLDMA late init failure
CVE-2026-72075await12.1LinuxLinuxInput: ims-pcu - fix race condition in reset_device sysfs callback
CVE-2026-72081await12.1LinuxLinuxscsi: elx: efct: Fix I/O leak on unsupported additional CDB
CVE-2026-72082await12.1LinuxLinuxscsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
CVE-2026-72087await12.1LinuxLinuxscsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
CVE-2026-72236await12.2LinuxLinuxs390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
CVE-2026-72276await12.1LinuxLinuxfbdev: metronomefb: fix potential memory leak in metronomefb_probe()
CVE-2026-72306await12.1LinuxLinuxvduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
CVE-2026-72437await12.1LinuxLinuxmd/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
CVE-2026-151427.512.0WebCodingPlaceReal Estate Manager ProCWE-269Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Esc…
CVE-2026-72011await11.8LinuxLinuxs390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
CVE-2026-68469await11.7LinuxLinuxwifi: mwifiex: fix permanently busy scans after multiple roam iterations
CVE-2026-142295.311.6UnknownECSCWE-284ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
CVE-2026-159486.411.5themeficHydra Booking — Appointment Scheduling & Booking CalendarCWE-79Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting vi…
CVE-2026-199041.911.5SourceCodesterOnline Book Store SystemCWE-79SourceCodester Online Book Store System System Settings index.php site_settin…
CVE-2026-68475await11.5LinuxLinuxreset: sunxi: fix memory region leak on ioremap failure
CVE-2026-68478await11.5LinuxLinuxmemstick: ms_block: reject a card that reports too many blocks
CVE-2026-72004await11.5LinuxLinuxwifi: mac80211: fix memory leak in ieee80211_register_hw()
CVE-2026-72010await11.5LinuxLinuxcgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
CVE-2026-72022await11.5LinuxLinuxllc: fix SAP refcount leak in llc_ui_autobind()
CVE-2026-72025await11.5LinuxLinuxs390/monwriter: Reject buffer reuse with different data length
CVE-2026-72038await11.5LinuxLinuxnet: liquidio: fix BAR resource leak on PF number failure
CVE-2026-72039await11.5LinuxLinuxbnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
CVE-2026-72047await11.5LinuxLinuxieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
CVE-2026-72048await11.5LinuxLinuxieee802154: ca8210: fix cas_ctl leak on spi_async failure
CVE-2026-72088await11.5LinuxLinuxscsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
CVE-2026-72138await11.5LinuxLinuxxen/gntdev: fix error handling in ioctl
CVE-2026-72140await11.5LinuxLinuxi2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
CVE-2026-72153await11.5LinuxLinuxirqchip/crossbar: Use correct index in crossbar_domain_free()
CVE-2026-72159await11.5LinuxLinuxocfs2: reject non-inline dinodes with i_size and zero i_clusters
CVE-2026-72163await11.5LinuxLinuxocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
CVE-2026-72182await11.5LinuxLinuxpower: supply: charger-manager: fix refcount leak in is_full_charged()
CVE-2026-72215await11.5LinuxLinuxMIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
CVE-2026-72218await11.5LinuxLinuxlockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
CVE-2026-72219await11.5LinuxLinuxlockd: Plug nlm_file leak when nlm_do_fopen() fails
CVE-2026-72228await11.5LinuxLinuxbatman-adv: frag: fix primary_if leak on failed linearization
CVE-2026-72229await11.5LinuxLinuxbatman-adv: clean untagged VLAN on netdev registration failure
CVE-2026-72230await11.5LinuxLinuxbatman-adv: frag: free unfragmentable packet
CVE-2026-72238await11.5LinuxLinuxx86/boot: Validate console=uart8250 baud rate to fix early boot hang
CVE-2026-72240await11.5LinuxLinuxmfd: sm501: Fix reference leak on failed device registration
CVE-2026-72241await11.5LinuxLinuxleds: uleds: Fix potential buffer overread
CVE-2026-72256await11.5LinuxLinuxnetfilter: xt_cluster: reject template conntracks in hash match
CVE-2026-72260await11.5LinuxLinuxASoC: mediatek: mt8192: Check runtime resume during probe
CVE-2026-72264await11.5LinuxLinuxfbdev: tridentfb: fix potential memory leak in trident_pci_probe()
CVE-2026-72265await11.5LinuxLinuxfbdev: nvidia: fix potential memory leak in nvidiafb_probe()
CVE-2026-72267await11.5LinuxLinuxfbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
CVE-2026-72268await11.5LinuxLinuxfbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
CVE-2026-72269await11.5LinuxLinuxfbdev: uvesafb: fix potential memory leak in uvesafb_probe()
CVE-2026-72270await11.5LinuxLinuxfbdev: s3fb: fix potential memory leak in s3_pci_probe()
CVE-2026-72271await11.5LinuxLinuxfbdev: i740fb: fix potential memory leak in i740fb_probe()
CVE-2026-72272await11.5LinuxLinuxfbdev: radeon: fix potential memory leak in radeonfb_pci_register()
CVE-2026-72401await11.4LinuxLinuxbpf: Fix insn_aux_data leak on verifier err_free_env path
CVE-2026-72428await11.5LinuxLinuxbpf: Fix stack slot index in nospec checks
CVE-2026-72433await11.5LinuxLinuxnetfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
CVE-2026-72479await11.5LinuxLinuxiio: accel: mma8452: handle I2C read error(s) in mma8452_read()
CVE-2026-72481await11.5LinuxLinuxiio: magnetometer: ak8975: fix potential kernel stack memory leak
CVE-2026-72484await11.5LinuxLinuxstaging: most: video: avoid double free on video register failure
CVE-2026-74284await11.5LinuxLinuxnet/sched: sch_hfsc: Don't make class passive twice
CVE-2026-72062await11.3LinuxLinuxgpio: mt7621: avoid corruption of shared interrupt trigger state
CVE-2026-72063await11.3LinuxLinuxgpio: tegra: do not call pinctrl for GPIO direction
CVE-2026-72070await11.3LinuxLinuxwifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
CVE-2026-72077await11.3LinuxLinuxInput: ims-pcu - fix firmware leak in async update
CVE-2026-72308await11.3LinuxLinuxmlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
CVE-2026-72324await11.3LinuxLinuxgpio: mvebu: free generic chips on unbind
CVE-2026-72325await11.3LinuxLinuxperf/x86/amd/core: Avoid enabling BRS from the SVM reload path
CVE-2026-72327await11.3LinuxLinuxdrm/v3d: Reject invalid indirect BO handle in indirect CSD setup
CVE-2026-72333await11.3LinuxLinuxBluetooth: L2CAP: fix tx ident leak for commands without a response
CVE-2026-72361await11.3LinuxLinuxdrm/xe/hw_engine: Fix double-free of managed BO in error path
CVE-2026-72376await11.3LinuxLinuxafs: Fix misplaced inc of net->cells_outstanding
CVE-2026-72379await11.3LinuxLinuxfs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
CVE-2026-72474await11.3LinuxLinuxdmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
CVE-2026-730559.311.1ericcornelissenshescapeCWE-116Shescape before 2.1.15 Home Directory Disclosure via BusyBox
CVE-2026-72321await11.0LinuxLinuxipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
CVE-2026-72341await11.0LinuxLinuxnet/mlx5e: Fix publication race for priv->channel_stats[]
CVE-2026-72365await11.0LinuxLinuxnetfs: Fix writethrough to use collection offload
CVE-2026-72060await11.0LinuxLinuxnet: ethernet: ti: icssg: guard PA stat lookups
CVE-2026-72092await11.0LinuxLinuxaccel/amdxdna: reject command submission on devices without a submit op
CVE-2026-72152await10.9LinuxLinuxtpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
CVE-2026-72155await10.9LinuxLinuxmtd: spi-nor: swp: Improve locking user experience
CVE-2026-72166await10.9LinuxLinuxnet/9p: fix infinite loop in p9_client_rpc on fatal signal
CVE-2026-72179await10.9LinuxLinuxriscv: cacheinfo: Fix node reference leak in populate_cache_leaves
CVE-2026-72363await11.0LinuxLinuxnetfs: Fix folio state after ENOMEM whilst under writeback iteration
CVE-2026-72384await10.9LinuxLinuxirqchip/ts4800: Fix missing chained handler cleanup on remove
CVE-2026-72392await10.9LinuxLinuxipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
CVE-2026-72445await11.0LinuxLinuxALSA: usb-audio: qcom: clear opened when stream enable fails
CVE-2026-72457await11.0LinuxLinuxapparmor: fail policy unpack on accept2 allocation failure
CVE-2026-72013await10.9LinuxLinuxriscv: Prevent NULL pointer dereference in machine_kexec_prepare()
CVE-2026-72037await10.9LinuxLinuxnet: lan743x: Initialize eth_syslock spinlock before use
CVE-2026-72086await10.9LinuxLinuxscsi: xen: scsiback: Free the command tag on the TMR submit-failure path
CVE-2026-72097await10.9LinuxLinuxdm-verity: fix a possible NULL pointer dereference
CVE-2026-72156await10.9LinuxLinuxfpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
CVE-2026-72161await10.9LinuxLinuxocfs2: add journal NULL check in ocfs2_checkpoint_inode()
CVE-2026-72167await10.9LinuxLinuxmtd: rawnand: pl353: fix probe resource allocation
CVE-2026-72177await10.9LinuxLinuxmm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
CVE-2026-72193await10.9LinuxLinuxntfs3: cap RESTART_TABLE free-chain walker at rt->used
CVE-2026-72214await10.9LinuxLinuxpower: supply: cpcap-battery: Fix missing nvmem_device_put() causing referenc…
CVE-2026-72257await10.9LinuxLinuxASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
CVE-2026-72274await10.9LinuxLinuxfbdev: hecubafb: fix potential memory leak in hecubafb_probe()
CVE-2026-72275await10.9LinuxLinuxfbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
CVE-2026-72290await10.9LinuxLinuxKVM: s390: pci: Fix GISC refcount leak on AIF enable failure
CVE-2026-72391await10.9LinuxLinuxnet: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
CVE-2026-72467await10.9LinuxLinuxxprtrdma: Check frwr_wp_create() during connect

Results continue: ranks 401–926.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-15 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.